Snort IDS and IPS Toolkit — Featuring Jay Beale and Members of the Snort Team

In this chapter we will explore the inner workings of Snort. We will start with how Snort is intialized, from processing command-line options to reading the configuration file. We then will move on to the more interesting aspect of Snort: packet processing. We will cover how Snort acquires packets, the intricacies of the packet decoder, analysis within the preprocessors, evaluation against the Snort rules, and finally, logging and alerting. Next, we will dive deeper inside the Snort detection engine. We'll take a look at some of the more complex rule options within Snort, and explain how Snort's pattern-matching engine functions and the different search algorithms. Once we have a firm understanding of how Snort currently works, we will explore one of the newest features in Snort, the dynamic detection engine. We'll look at what the dynamic detection is, and we'll cover, in detail, the API it provides for writing Snort rules in C.
Before we dive into the details of how Snort processes packets, you should understand how Snort starts up and how it handles tasks outside of the packet processing loop. Snort startup involves three phases. First the command-line arguments are parsed. These help to determine how Snort will be running as well as setting a variety of configuration variables. Next, if specified in the command line, Snort processes its configuration file. This file contains configuration details that are too complex for the command line, as well as rules, preprocessor configurations, and output plug-in configurations. Finally,...